I found the following in my /var/log/messages Dec 25 14:31:59 myhost portsentry[1413]: attackalert: UDP scan from host: gateway/192.168.1.254 to UDP port: 53 Dec 25 14:31:59 myhost portsentry[1413]: attackalert: Host 192.168.1.254 has been blocked via wrappers with string: "ALL: 192.168.1.254" Dec 25 14:31:59 myhost portsentry[1413]: attackalert: Host 192.168.1.254 has been blocked via dropped route using command: "/sbin/ipchains -I input -s 192.168.1.254 -j DENY -l" This is strange as the gateway is a cisco router, and my machine doesnt run named. any comments? is this serious? thanks St. -- SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ More Info: http://lists.slug.org.au/listinfo/slug
